Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226571 4.6 警告 シスコシステムズ - Cisco NX-OS の tar におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-4131 2013-12-24 19:07 2013-12-23 Show GitHub Exploit DB Packet Storm
226572 7.5 危険 INNER ESTEEM SDN BHD - C2C Forward Auction Creator における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-7193 2013-12-24 18:58 2013-12-14 Show GitHub Exploit DB Packet Storm
226573 7.5 危険 INNER ESTEEM SDN BHD - Dynamic Biz Website Builder における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-7192 2013-12-24 18:57 2013-12-16 Show GitHub Exploit DB Packet Storm
226574 4.3 警告 Tenmiles - Tenmiles Helpdesk Pilot におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-7191 2013-12-24 18:52 2013-12-6 Show GitHub Exploit DB Packet Storm
226575 9.3 危険 Steinberg Media Technologies GmbH - Steinberg MyMp3PRO におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-7186 2013-12-24 18:48 2013-12-5 Show GitHub Exploit DB Packet Storm
226576 5 警告 Digium - 複数の Asterisk 製品の apps/app_sms.c の unpacksms16 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-7100 2013-12-24 18:47 2013-12-16 Show GitHub Exploit DB Packet Storm
226577 4.7 警告 NovaTech - 複数の Orion Substation Automation Platform 製品におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-2822 2013-12-24 18:30 2013-12-18 Show GitHub Exploit DB Packet Storm
226578 7.1 危険 NovaTech - 複数の Orion Substation Automation Platform 製品におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-2821 2013-12-24 18:30 2013-12-18 Show GitHub Exploit DB Packet Storm
226579 7.2 危険 クイックヒール・テクノロジーズ・ジャパン株式会社 - Quick Heal AntiVirus Pro の pepoly.dll におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-6767 2013-12-24 18:27 2013-12-16 Show GitHub Exploit DB Packet Storm
226580 6.8 警告 Idleman - Leed の action.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-2628 2013-12-24 18:06 2013-12-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
951 7.5 HIGH
Network
wolfssl wolfssl AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reuse, and consequent p… CWE-323
 Reusing a Nonce, Key Pair in Encryption
CVE-2026-55967 2026-06-27 01:50 2026-06-26 Show GitHub Exploit DB Packet Storm
952 7.5 HIGH
Network
wolfssl wolfssl wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an object has empty signerInfos, so the underlying signed-data verification succeeds… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-55961 2026-06-27 01:50 2026-06-26 Show GitHub Exploit DB Packet Storm
953 7.5 HIGH
Network
wolfssl wolfssl X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra whose application … CWE-295
Improper Certificate Validation 
CVE-2026-11999 2026-06-27 01:50 2026-06-26 Show GitHub Exploit DB Packet Storm
954 9.8 CRITICAL
Network
dest-unreach socat socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension … CWE-122
Heap-based Buffer Overflow
CVE-2026-56123 2026-06-27 01:50 2026-06-26 Show GitHub Exploit DB Packet Storm
955 3.3 LOW
Local
tenable nessus A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potent… CWE-89
SQL Injection
CVE-2026-57588 2026-06-27 01:48 2026-06-26 Show GitHub Exploit DB Packet Storm
956 5.3 MEDIUM
Network
tenable nessus A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potential… CWE-89
SQL Injection
CVE-2026-57587 2026-06-27 01:47 2026-06-26 Show GitHub Exploit DB Packet Storm
957 5.3 MEDIUM
Network
nokogiri nokogiri Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPathContext did not keep its source document alive for garbage collection. If an XP… CWE-416
 Use After Free
CVE-2026-57437 2026-06-27 01:47 2026-06-26 Show GitHub Exploit DB Packet Storm
958 5.3 MEDIUM
Network
nokogiri nokogiri Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Document#root= validated only that the new root was a Nokogiri::XML::Node, allowing … CWE-416
 Use After Free
CVE-2026-57436 2026-06-27 01:47 2026-06-26 Show GitHub Exploit DB Packet Storm
959 3.8 LOW
Network
mattermost mattermost_server Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts vi… CWE-863
 Incorrect Authorization
CVE-2026-8823 2026-06-27 01:39 2026-06-23 Show GitHub Exploit DB Packet Storm
960 10.0 CRITICAL
Network
traefik traefik Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to byp… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-53622 2026-06-27 01:39 2026-06-24 Show GitHub Exploit DB Packet Storm